Legal · Global
Privacy Policy
This policy applies to users worldwide. It explains what we collect, why we process it, and the rights available to you under international privacy laws.
Last updated: July 2026
Scope and controller
Instrm, Inc. ("Instrm," "we," "us") operates an international live streaming platform available at instrm.com and related domains. We act as the data controller for account, billing, and platform operations data described in this policy.
When you broadcast, you may collect viewer information (names, passcodes, waiting-room requests). In those cases, you are the controller for viewer data and Instrm processes it on your behalf to deliver the Service. You are responsible for providing appropriate notices to your viewers and complying with laws that apply to your broadcasts.
This policy is provided in English. If translated, the English version controls except where local law requires otherwise.
Information we collect
Depending on how you use Instrm, we may collect:
- Account data: username, email, authentication identifiers (including from Google sign-in), and account preferences.
- Stream and production data: titles, distribution settings, RTMP credentials, simulcast destinations, waiting-room rules, and operational metrics.
- Viewer data: display names, access requests, passcodes you require, playback tokens, and session telemetry needed to deliver video securely.
- Payment data: plan tier, invoices, transaction references, and tax information. Card numbers are handled by our payment processor, not stored by Instrm.
- Technical data: IP address, device and browser type, timestamps, logs, security signals, and diagnostic data.
- Communications: support messages and correspondence with our team.
Legal bases for processing (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal data on these legal bases:
- Contract: to provide the Service you request, including ingest, simulcast, viewer access, and billing.
- Legitimate interests: to secure the platform, prevent abuse, improve reliability, and communicate about the Service (balanced against your rights).
- Consent: where required, such as optional marketing or non-essential cookies if enabled in your region.
- Legal obligation: to comply with tax, accounting, and lawful requests.
Lawful processing in other jurisdictions
Outside the EEA, UK, and Switzerland, we process personal data where we have a lawful basis under applicable local law, including:
- Performance of our contract with you
- Your consent, where required
- Legitimate interests that are not overridden by your rights
- Compliance with legal obligations
We design our practices to align with widely recognized frameworks, including GDPR and UK GDPR principles, Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act, India's Digital Personal Data Protection Act, Singapore's PDPA, South Africa's POPIA, Japan's APPI, and comparable laws in other countries where users access the Service.
How we use information
We use personal data to:
- Create and manage accounts and authenticate users
- Ingest, transcode, route, and deliver live streams
- Operate waiting rooms, passcodes, and viewer access controls
- Process subscriptions, session passes, and payments
- Monitor health, prevent fraud, and maintain security
- Provide support and service communications
- Comply with law and enforce our terms
We do not use your stream content for advertising profiling. We do not sell personal information as defined under the California Consumer Privacy Act (CCPA), as amended by the CPRA.
How we share information
We share data only as needed to operate Instrm:
- Destinations you choose: YouTube, Facebook, Twitch, custom RTMP endpoints, and other platforms you configure, each under their own policies.
- Service providers: hosting, media delivery, payments, email, analytics, and security vendors bound by confidentiality and data protection terms.
- Corporate transactions: merger, acquisition, or asset sale, subject to continued protection of personal data.
- Legal and safety: to comply with law, enforce agreements, or protect users and the public.
See our Security page for an overview of safeguards.
International data transfers
Instrm is a global service. Your data may be processed in the United States and other countries where we or our providers operate. When we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses and supplementary measures where required.
You may request more information about transfer safeguards by contacting privacy@instrm.com.
Retention
We retain personal data while your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and meet legal obligations. Operational logs are kept for limited periods. When data is no longer required, we delete or anonymize it unless retention is legally required.
Your privacy rights by region
Rights vary by location. Subject to verification and applicable exceptions, you may have the right to access, correct, delete, restrict, object to processing, or receive a portable copy of your personal data.
European Economic Area, United Kingdom, and Switzerland
- Right to withdraw consent where processing is consent-based
- Right to lodge a complaint with your local supervisory authority
- Right to object to processing based on legitimate interests or for direct marketing
EEA, UK, and Swiss residents may contact privacy@instrm.com for data protection inquiries. We respond in accordance with applicable GDPR and UK GDPR timelines.
United States (California and similar state laws)
- Right to know categories and specific pieces of personal information collected
- Right to delete personal information, subject to exceptions
- Right to correct inaccurate personal information
- Right to opt out of sale or sharing of personal information (Instrm does not sell personal information)
- Right to limit use of sensitive personal information where applicable
- Right to non-discrimination for exercising privacy rights
Residents of Colorado, Connecticut, Virginia, Utah, and other U.S. states with comprehensive privacy laws may have similar rights. Submit requests to privacy@instrm.com.
Americas (Brazil, Canada, Mexico, and others)
- Brazil (LGPD): confirmation of processing, access, correction, anonymization, portability, deletion, and information about shared data
- Canada (PIPEDA and provincial laws): access, correction, and withdrawal of consent, subject to legal exceptions
- Mexico (LFPDPPP): access, rectification, cancellation, and opposition (ARCO rights)
Africa
- South Africa (POPIA): access, correction, deletion, and objection
- Ghana, Nigeria, Kenya, and other jurisdictions: rights under local data protection legislation, including confirmation and correction of personal data
Asia-Pacific
- Australia and New Zealand: access and correction under applicable privacy legislation
- India (DPDP Act): access, correction, erasure, and grievance redressal
- Singapore (PDPA), Japan (APPI), South Korea (PIPA), Philippines, and Indonesia: rights to access, correct, and withdraw consent where required
Middle East and other regions
Residents subject to local data protection laws (including the UAE, Saudi Arabia, and other jurisdictions) may exercise rights granted by those laws by contacting privacy@instrm.com. We honor valid requests consistent with applicable legislation.
Submit requests at privacy@instrm.com or via our contact form. We respond within timelines required by your jurisdiction (for example, 30 days under GDPR, 45 days under CCPA where applicable).
Cookies and similar technologies
We use essential cookies and local storage for authentication, security, and core functionality. Where required by law in your region, we will request consent before placing non-essential cookies. You can control cookies through your browser settings. Disabling essential cookies may prevent you from using parts of the Service.
We do not respond to browser "Do Not Track" signals because there is no uniform industry standard. You may manage cookies and exercise privacy rights as described in this policy and through the cookie notice shown on our site.
Automated decision-making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you. We may use automated systems for fraud prevention, abuse detection, and stream health monitoring.
Children
Instrm is not directed to children. We do not knowingly collect personal information from anyone under 13 (United States), under 16 where required in the EEA, or under the minimum digital consent age in your country. If you believe we collected a child's data, contact privacy@instrm.com and we will delete it promptly.
Changes
We may update this Privacy Policy to reflect legal, technical, or business changes. We will post the new version on this page with an updated date. Material changes may be notified by email or in-product notice where required by law.
Contact
Privacy questions and data subject requests:
Instrm, Inc.
Global service. Privacy and legal requests are handled in English. Where local law requires, we respond in accordance with applicable regional obligations.
General: hello@instrm.com
Privacy requests: privacy@instrm.com
Support: support@instrm.com
Security: security@instrm.com